|
247281
|
8.1 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wir…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10694
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247282
|
7.5 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to downloa…
|
CWE-284
Improper Access Control
|
CVE-2018-10691
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247283
|
8.1 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allow…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10690
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247284
|
6.1 |
MEDIUM
Network
|
lantronix
|
securelinx_spider_firmware
|
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10383
|
2024-11-21 12:41 |
2019-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247285
|
9.8 |
CRITICAL
Network
|
oisf
|
suricata
|
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-comm…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10244
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247286
|
9.8 |
CRITICAL
Network
|
oisf
|
libhtp
|
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10243
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247287
|
7.5 |
HIGH
Network
|
oisf debian
|
suricata debian_linux
|
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10242
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247288
|
9.8 |
CRITICAL
Network
|
codesys
|
control_for_beaglebone_sl control_for_empc-a\/imx6_sl control_for_iot2000_sl control_for_linux_sl control_for_pfc100_sl control_for_pfc200_sl control_for_raspberry_pi_sl control_…
|
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker…
|
CWE-311 CWE-732
Missing Encryption of Sensitive Data Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10612
|
2024-11-21 12:41 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247289
|
7.2 |
HIGH
Network
|
netgain-systems
|
enterprise_manager
|
NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary co…
|
CWE-78
OS Command
|
CVE-2018-10587
|
2024-11-21 12:41 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247290
|
4.8 |
MEDIUM
Network
|
netgain-systems
|
enterprise_manager
|
NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions before 10.1.12.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10586
|
2024-11-21 12:41 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|